Merge pull request #201 from newpavlov/streebog1

Add an advisory for streebog bug
This commit is contained in:
Tony Arcieri
2019-11-06 11:41:53 -08:00
committed by GitHub

View File

@@ -0,0 +1,13 @@
[advisory]
id = "RUSTSEC-0000-0000"
package = "streebog"
date = "2019-10-06"
title = "Incorrect implementation of the Streebog hash functions"
description = """
Internal `update-sigma` function was implemented incorrectly and depending on
`debug-assertions` it could've caused an incorrect result or panic for certain
inputs.
"""
patched_versions = [">= 0.8.0"]
url = "https://github.com/RustCrypto/hashes/pull/91"
category = ["crypto-failure"]